Connect with us

NEWS

Huang Sells Cybersecurity as AI’s Next Always-On App

Huang pitched cybersecurity as AI’s next always-on market, a loop Gartner sees jumping 98% in 2026 as attackers use the same tools.

Published

on

Nvidia CEO Jensen Huang told investors on September 10, 2026 that cybersecurity will likely be AI’s next major use case. He spoke at Goldman Sachs’ Communacopia + Technology Conference in San Francisco, nine days after he stood with CrowdStrike in Las Vegas to launch a defense system built to run without waiting for a prompt.

Coding assistants still answer when someone asks. Huang said the next product keeps hunting bugs and blocking attacks, a loop companies would pay to leave on.

Huang Tied the Market to a Problem He Helps Create

Huang’s chain was blunt. “A derivative of coding is, of course, bug finding,” he said. “And a derivative of that, which is a very large market, is called cybersecurity.” Models that write software also find holes in software, and someone has to close those holes as fast as they open.

He did not sell that as charity. He sold it as demand, and he said the quiet part in the room.

What better way to create demand than to create a problem. Who doesn’t want their market to be hysterical about their product and line up around the corner for it? And so there are responsible ways of doing it and there’s less attractive ways of doing it.

Jensen Huang, CEO, Goldman Sachs Communacopia + Technology Conference

That line is the business version of a warning labs have been logging in public. If models can draft exploits at machine speed, buyers will pay for models that catch them at machine speed. Nvidia sells the chips for both jobs. Huang was not asked to referee the safety fight that follows from that overlap, and he did not volunteer.

He still drew a line. There are, he said, responsible ways to stoke that market and less attractive ones. The responsible path, in his telling, is automated defense that never clocks out. OpenAI chief financial officer Sarah Friar told the same Goldman conference that cybersecurity is a major commercial opportunity, which is how you know the pitch has left the lab and entered the sales cycle.

Anthropic’s 832 Banned Accounts Map the Attack Side

Huang’s forecast landed on the same date Anthropic released a new threat-intelligence report on people who had used Claude for cyberattacks, surveillance, biology work, and weapons design. The sales speech and the ban list describe one skill from two desks.

The numbered picture sits in an earlier Anthropic study. On June 3, 2026, researchers Kyla Guru, Alex Moix, and Jacob Klein mapped a year of banned Claude use onto the MITRE ATT&CK catalog, the standard menu of attacker moves. They took 832 accounts tied to malicious cyber activity from March 2025 through March 2026, a subset of bans that had enough detail to code, and scored how much the model helped.

WHAT ANTHROPIC CODED IN THE BANNED SAMPLE

  • The volume: 13,873 observed actions covering all 14 ATT&CK tactics and 482 unique techniques.
  • The risk shift: Actors scored medium risk or higher rose from 33% in the first half of the year to 56% in the second, about a 1.7 times increase, with the gain in high-harm steps such as credential dumping and web shells.
  • The most common ask: 69% of the accounts, 574 of 832, used the model to develop capabilities, mostly custom malware.
  • Defense evasion: 84.4% of the actors sought help hiding from security tools, the single largest tactic group in the set.
  • The gap: Only 6.5%, 54 of 832, used the model for lateral movement once inside a network, which is where Anthropic says agent scaffolding, not extra chat skill, will matter next.

The June paper also points at a campaign Anthropic disrupted in mid-September 2025. A Chinese state-sponsored group labelled GTG-1002 used Claude Code to run reconnaissance, find bugs, exploit them, move inside networks, and pull data with little human steering. Anthropic called it the first case it had documented of a cyberattack carried out largely without a person at each step.

Later reviews of cybersecurity tests found four incidents in which Claude models, told they were in a sealed simulation, reached live systems at outside organizations after the test network was left open to the internet. The models were not a sci-fi breakout. They were tools finishing an assigned hacking task after the cage failed.

Mythos Preview, Anthropic’s own cyber-eval model, is already finding and exploiting bugs at a level the lab compares with skilled human researchers. Huang’s “derivative of coding” is not a slide. It is in production on both sides of the firewall.

Why Always-On Defense Beats a Coding Chatbot

Huang said cybersecurity AI will run on constant red-teaming and blue-teaming, which makes it a large and ongoing market for AI systems. A coding assistant bills when a person types. A red-and-blue loop bills for as long as the attack surface exists, which is the entire life of the network.

That is the part of the pitch that matters to a chip vendor. Chatbots and coding agents still run in bursts. A defender that has to match an attacker who never sleeps does not get to park the GPUs. The workload scales with the size of the threat surface, not with how many analysts are on the clock.

Huang also repeated that he is confident Nvidia can grow revenue 70% year over year, even though unconstrained demand is growing at more than 100% and supply, land, and power are the brakes. A product that never idles is how a use case turns into occupancy. Cyber is cleaner on that math than another chatbot feature, because the adversary keeps moving and the bill keeps running.

The ugly twin of that math is that the same loop arms the other team. Attackers need one opening. Defenders have to cover the whole surface. A copilot that waits for a ticket still leaves a human in the critical path. Huang is selling the version that does not wait, which is also the version that makes a missed detection cost more, faster.

CrowdStrike, Cisco, and Palantir Already Ship the Loop

On September 1, 2026, at CrowdStrike’s sold-out Fal.Con in Las Vegas, Huang put the same idea in shorter words. “We’re at an inflection point in cybersecurity,” he told the room. “Attacks are now automated. Defense has to be, too.” He joined CrowdStrike founder and CEO George Kurtz to announce SafeMind, an agentic system from CrowdStrike’s Cyber Superintelligence Lab, built on Nvidia Nemotron open models post-trained on CrowdStrike’s own threat data.

SafeMind is not a chat window with a padlock icon. Nvidia Nemotron 3 Ultra runs the defensive agent harness. A fine-tuned Nemotron 3 Super powers a rule-generation sub-agent. CrowdStrike’s own tests of Blue Solano, the Nemotron 3 Super defensive model, showed higher accuracy than leading frontier models at 99% lower cost. The pairing on the other side of the ring is Red Tempest, a purpose-built offensive model that attacks so Blue Solano can learn. Offense and defense train against each other in a closed loop, including, Huang said, in a digital twin of Nvidia.

This isn’t a copilot baked into someone else’s intelligence. It’s not a chatbot with a security skin. It is a frontier-class model built and trained by CrowdStrike on our data in partnership with NVIDIA.

George Kurtz, CEO, Fal.Con 2026

THE NVIDIA CYBER STACK

Partner Product What it does
CrowdStrike SafeMind (Blue Solano and Red Tempest) Post-trains Nemotron on Falcon data and runs a continuous offense-defense loop inside the Falcon platform
Cisco and Palantir Secure AI Factory plus Ontology for Cybersecurity Puts Nemotron, Cisco Cloud Control, and Palantir Foundry on a sovereign stack for firms that will not send data out
Open Secure AI Alliance NOOA harness, open weights, shared tools Gives defenders inspectable models and agent plumbing instead of a single closed vendor

The Cisco and Palantir leg arrived on the same morning as the Goldman remarks. Cisco president and chief product officer Jeetu Patel wrote that Cisco, Palantir, and Nvidia are extending a secure custom AI platform to companies and countries, with a focus on cybersecurity. Cisco’s Secure AI Factory with Nvidia is the preferred full-stack base for Palantir’s Sovereign AI OS, using Nemotron open models to run Palantir’s Ontology for Cybersecurity and Palantir Foundry plus AIP for security and IT teams that want the model on their own floor.

Patel’s frame is intelligence, cost, and control. Raw benchmark scores, he wrote, are the wrong test; a fraud pipeline, a help-desk agent, and a classified workload that cannot leave a building want different models. Post-training an open model such as Nemotron on a firm’s own data can beat a smarter closed model on the job that actually pays. That is how Nvidia turns a software story into racks that stay bolted down.

THE DATES BEHIND THE PITCH

  1. July 27, 2026: Nvidia and a long list of vendors launch the Open Secure AI Alliance to share open defensive tools after a Hugging Face incident in which closed models blocked forensic work.
  2. September 1, 2026: Huang and Kurtz launch SafeMind at Fal.Con, with Nemotron 3 Ultra and Nemotron 3 Super inside the agent stack.
  3. September 10, 2026: Huang tells Goldman cybersecurity is the next major AI use case, Patel publishes the Cisco-Palantir factory note, and Anthropic drops a new misuse report.

Three beats in six weeks is not a thought experiment. It is a product calendar that was already moving when Huang gave the line its slogan.

AI Cybersecurity Spend Is on Track to Jump 98% in 2026

The money trail is already bending toward the pitch. Gartner’s May 2026 AI spending forecast puts an AI cybersecurity line of $51.347 billion in 2026, up 98% from $25.920 billion in 2025, and $85.997 billion in 2027. That category is AI used to defend systems, the thing Huang was pricing, not the smaller niche of tools that only lock down models themselves.

GARTNER AI CYBERSECURITY SPEND

Year Forecast spend
2025 $25.920 billion
2026 $51.347 billion
2027 $85.997 billion

John-David Lovelock, a distinguished vice president analyst at Gartner, said vendors and hyperscalers have been the ones spending so far, and that 2026 is when enterprises start to flex. If Huang is right that the buyer will pay for a process that never stops, that flex shows up as inference that does not go idle at 5 p.m., which is a different purchase from a seat license for a coding bot.

It is also a purchase that does not care which logo wins the SOC. CrowdStrike, Palo Alto, Cisco, Cloudflare, and Zscaler can all field a stack. Each stack still needs accelerated compute. Nvidia’s bet is underneath the logo fight, which is why Huang can bless a “number one” partner on a Tuesday and a Cisco-Palantir factory on a Thursday without contradicting himself.

Open Models Are Nvidia’s Defense Pitch

The July alliance is the ideological half of the same sale. Nvidia’s post argues that defenders need inspectable open models they can run on their own iron, because a closed tool that cannot tell a defender from an attacker will freeze at the worst moment. In the Hugging Face incident the post cites, closed systems blocked forensic analysis, so the company ran the open-weight GLM 5.2 model on its own machines to review more than 17,000 actions and contain the break-in.

Nvidia says it is contributing open models, weights, and agent harness research to that club, including the NVIDIA Labs Object-Oriented Agent project, which is meant to make agent behavior easier to test, trace, and audit. Microsoft’s MDASH harness, listed in the same post, orchestrates agents that discover, debate, and prove exploitable bugs. The defense alliance includes an automated bug finder. That is Huang’s coding-to-cyber chain in software form.

OpenAI, Anthropic, and Google do not appear on Nvidia’s published inaugural partner list. The labs most identified with closed frontier models are outside the open-defense tent Nvidia is pitching to governments. Huang had already made the political case on his own account, writing that open models strengthen safety and cybersecurity and that every developer, startup, university, industry, and country should be able to build with them.

The alliance post tells regulators not to treat open frontier systems as a liability, warning that blanket limits would weaken defensive capacity and concentrate failure in a few closed providers. That is a sincere argument about inspectability. It is also how Nvidia keeps Nemotron, and the GPUs under it, in the path of every national SOC that refuses to ship logs to a US chatbot.

The Red and Blue Loop Does Not Stop

Huang’s Goldman remarks did not invent a market. They named a loop Nvidia had already wired into SafeMind, into a Cisco-Palantir factory, and into an open-model club that treats bug finding as shared infrastructure. Coding was the first blockbuster because people type. Cyber is the sequel because networks do not clock out, and because the same models that patch a hole can cut a new one.

Anthropic’s September 10 report and Huang’s San Francisco forecast describe the same techniques on the same date. One landed as a sales outlook. The other landed as a ban list.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending